CVE-2025-8342 Details
Description
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes it possible for unauthenticated attackers to bypass OTP verification and gain administrative access to any user account with a configured phone number by exploiting improper Firebase API error handling when the Firebase API key is not configured.
A vulnerability allowing authentication bypass has been identified in the WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress, affecting all versions through 1.8.47. The issue arises from inadequate validation of empty values in the lwp_ajax_register function, which enables unauthenticated attackers to bypass OTP verification. Exploitation of this vulnerability can lead to unauthorized administrative access on user accounts with a registered phone number, by taking advantage of flawed error handling in the Firebase API when the Firebase API key is not set up.
Users are advised to update the WooCommerce OTP Login With Phone Number, OTP Verification plugin to version 1.8.48 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 15, 2025CISA-ADP
Assessed Aug 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WooCommerce OTP Login With Phone Number | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 15, 2025 | New CVE Received | [email protected] |
Volerion